Security Report AI

Data processing agreement

The scope of the agreement between the customer as controller and the operating entity as processor.

Status

PLACEHOLDER — the data processing agreement is prepared in outline but is not approved and not offered for signature. Until it is executed, processing terms are those of the written pilot agreement. The outline below shows exactly what the final document will cover.

Current state: draft. Commercial and operational variables still to be fixed: governingLaw, venue, dataLocation, transferMechanism, breachNotificationHours, deletionAfterTerminationDays, subprocessorChangeNoticeDays, auditRights, liabilityReference.

What the agreement covers

  • • 1. Parties and roles — Identifies the customer as controller and the operating entity as processor, with the identity details taken from the brand configuration.
  • • 2. Subject matter, duration and nature of processing — Incident reporting, SOP retrieval and procedure support for a hotel security department, for the duration of the subscription.
  • • 3. Categories of data subjects and personal data — Workspace users (account and role data) and any individuals named in incident narratives, transcripts or uploaded procedures.
  • • 4. Processor obligations and documented instructions — Processing only on documented instructions, confidentiality of personnel, and no use of customer content to train models.
  • • 5. Security measures — Annex referencing the controls actually implemented in the product; no certification is asserted.
  • • 6. Sub-processors — General authorisation with a published register and prior notice of changes.
  • • 7. International transfers — Data location and the mechanism covering any transfer outside the EEA.
  • • 8. Assistance to the controller — Support with data-subject requests, DPIAs and prior consultation, including the in-product export.
  • • 9. Personal data breach notification — Notification without undue delay and within the agreed window.
  • • 10. Audit and information rights — How the controller may verify compliance.
  • • 11. Return and deletion of data — What happens to workspace data after termination.
  • • 12. Liability, governing law and venue — Alignment with the master agreement.
  • • Annex A — Processing details — Tabular summary of purposes, data categories and retention.
  • • Annex B — Technical and organisational measures — The verified controls listed on the Security page, nothing beyond them.
  • • Annex C — Approved sub-processors — Generated from the sub-processor register once published.

Until it is executed

No compliance status is asserted and nothing on this page is an offer to contract. Processing during the pilot is governed by the written pilot agreement; ask your pilot contact for the current text before entering production data.

Contact

  • • The operating entity, its registered address, VAT number and published contact addresses are not confirmed yet. They are provided in writing to each pilot customer before any data is entered, and will be listed here once registered.
Back to home